Cyber Security Engineer required work with a Government Department. This is a 5 month contract, paying £700 per day, inside IR35, hybrid working (2 days per week on-site in London)
You will be required to have an active SC Clearance
You will join the Application Security Team. This is an AppSec team focused on building security automation into delivery pipelines and conducting security focused tests against digital services.
Key Responsibilities
- Perform penetration testing and vulnerability assessments of web applications, APIs, and cloud infrastructure.
- Evaluate the automated security tooling into CI/CD pipelines (SAST, DAST, dependency checking, IaC etc), and make necessary recommendations.
- Collaborate with developers to remediate identified vulnerabilities and ensure secure code practices.
- Provide expert input on cloud security (AWS, Azure, or GCP) and DevSecOps tooling.
- Assist in maintaining security assurance across the SDLC in line with NCSC guidelines.
Essential Criteria
- Penetration testing, ethical hacking, or vulnerability assessments.
- Security testing tools (e.g., Burp Suite, OWASP ZAP, Nikto, Nmap, Metasploit, etc.).
- DevSecOps principles and tools (e.g., Veracode, SonarQube, GitHub Advanced Security, IaC scanning, etc.).
- Secure Cloud Infrastructure, specifically AWS and Azure.
- Scripting and automation using Python and Bash.
- Certifications: OSCP or CREST / TIGER Scheme.
- Strong communication skills and the ability to explain security issues to technical and non-technical stakeholders.
- Experience delivering assessments under the CHECK scheme (e.g., as a CHECK Team Member/Leader).
- Knowledge of UK public sector security and data protection standards (e.g., NCSC, Cyber Essentials Plus).
- Threat modelling and secure design practices.
Please apply should you meet the above criteria
Attenti Consulting is acting as an Employment Business in relation to this vacancy.